Detect sudden activity from long-dormant Service Principals and App Registrations that may indicate compromised client secrets or abandoned credentials.
Monitor high-privilege Azure RBAC grant operations (Owner, Contributor, User Access Administrator) in AzureActivity logs using proactive KQL alert rules.
Identify anomalous mass file download operations and data hoarding across SharePoint Online and OneDrive for Business using statistical KQL baseline thresholds.